If you want to hunt for signs of Certighost (CVE-2026-54121) by @h0j3n and @aniqfakhrul in your #XDR environment try this query.
1. Exclude DCs
2. Identify ADCS servers
3. Check for LDAP or SMB connectivity to any non DC from ADCS
BP for SMB possible!
https://t.co/BGOhTzsP40
New #ClickFix campaign leverages on-the-fly WebAssembly and #steganography through SVG files. Pages from legitimate but compromised sites lead to fake verification pages that instruct viewers to paste content into a Run window. Details at https://t.co/BRhEjIdsDg
⚠️ Attackers can validate stolen #Microsoft Entra credentials without generating a successful sign-in event.
Researchers tracked two campaigns using spoofed OAuth client IDs, including one that targeted over 2 million users. App-scoped detections may miss it.
Read why Entra logs may miss it: https://t.co/P9O6RrPx7B
@fabian_bader@sapirxfed Yes, I’ve updated the slides with minor changes to my talk at HIPConf. There’s also a recording of the session. Unfortunately, the most fun part - the live demos of my queries - wasn’t captured: https://t.co/pv1rLA6yxB
Adding to this list. All free. No paywall. No signup.
https://t.co/x516DQRcB8 - 700+ pages of malware analysis and exploit research
https://t.co/cgxRDKvx2g - full university malware analysis course
https://t.co/7uSbDhTq6s - RE101, RE102, macOS RE, PE injection
https://t.co/mRHslgjr4f - ARM assembly, shellcode, heap exploitation
https://t.co/SLm7Vlyd93 - applied RE series and hypervisor development
https://t.co/3SLFBf6xSp - buffer overflows to kernel exploitation
https://t.co/gDWRH5YpIx - 30+ courses, WinDbg, IDA, Ghidra, UEFI, kernel exploitation
https://t.co/rA4x1Hv2iE - 41 tutorials spanning 17 years of exploit dev
https://t.co/DIqWzR1Xp3 - 19-part series, usermode to kernel
https://t.co/BJpRHdbTHu - Windows internals, secure kernel, VBS, KDP, dynamic analysis
YouTube:
https://t.co/KLUDZ9us2g
https://t.co/yxJUVqTzvK
https://t.co/IvelLJIQhH
https://t.co/C8aErWJ5RJ
https://t.co/NDG3swCvB1
Thousands of dollars worth of knowledge. All free.
#ReverseEngineering #MalwareAnalysis #InfoSec
While investigating wiping attacks, Microsoft Threat Intelligence uncovered GigaWiper, a destructive backdoor that combines multiple wiping and ransomware-like capabilities into one implant. https://t.co/0oNhvPUX76
Our analysis found that the backdoor embeds previously separate malware families as on-demand commands: a standalone disk wiper, code derived from Crucio ransomware, and a reimplementation of the FlockWiper wiper in Golang.
Read our latest blog for a code-level analysis of GigaWiper, detailed breakdowns of its persistence, command-and-control, and destructive capabilities, and guidance to help defenders investigate, detect, and defend against similar threats.
The bug sits in SSH packet parsing during the handshake.
libssh2 rejected packet_length values below 1, but missed the upper bound.
A value like 0xffffffff can wrap the allocation math, create a tiny buffer, then let an oversized packet write past it.
⚠️ Attackers hid their backdoor traffic inside Microsoft Teams relay infrastructure.
DragonForce used a custom Go backdoor to make C2 traffic look like trusted Teams traffic.
That makes detection harder without blocking normal business tools.
Read 🠖 https://t.co/OzqQxcZNgf
Shai-Hulud Campaign Evolution
The tables below extend the V1/V2 comparison from our earlier post across subsequent waves. V1 and V2 are included as baselines.
‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.
Microsoft has patched it as CVE-2026-42824, rated critical.
'On 3 June 2026, members of the Five Eyes intelligence partnership (ASIO, CSIS, FBI, MI5 and NZSIS) released a joint bulletin, Safeguarding our Secrets, warning of the threat posed by China's military intelligence services on Western professional networking sites and online job platforms.'
https://t.co/B56Q5XGHxt
Yeah, so pretty much this guy is releasing an exploit in solidarity with Nightmare Eclipse guy. He said he notified GitHub about the exploit 60 minutes before releasing this paper.
I don't do web stuff, and I'm not a VSCode nerd, so I'm confused by the underlying technologies.
If you're a stinky GitHub and VSCode nerd maybe you'll understand.
tl;dr click github dev, github dev opens editor, in github dev editor have javascript, javascript does shortcuts automatically. github treats javascript shortcuts as real human input, or something. use javascript shortcut stuff to automatically install vscode extension. the vscode extension steals your data
tl;dr tl;dr user clicks 1 link, 1 click steals all data from your github
https://t.co/uh17usZeEH